## 1ttoea2023002

## Source details

**Canonical URL:** [1ttoea2023002](https://www.imf.org/-/media/files/publications/cr/2023/english/1ttoea2023002.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2023/english/1ttoea2023002.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2023/english/1ttoea2023002.pdf.json)

---

### Mission purpose and scope
- At the request of the Central Bank of Trinidad and Tobago (CBTT), the Monetary and Capital Markets Department (MCM) provided a field based technical assistance (TA) mission on strengthening cybersecurity in financial institutions during October 31 to November 4, 2022.
- Mission objectives:
  - (i) to strengthen the cybersecurity of the financial institutions under the supervisory ambit of CBTT; and
  - (ii) to strengthen the cybersecurity posture of the Central Bank.
- Meetings: The mission met the Governor on the first day and met Patrick Solomon (Inspector), Michelle Francis-Pantor (Deputy Inspector) from Financial Institutions Supervision Department (FISD) and Frances Correa (IT Consultant) and their team members.
- Output: This report presents the mission’s assessment and main conclusions.

### Deliverables and initial arrangements
- Deliverables included:
  - A capacity building seminar on regulation of cyber risk (delivered November 1–3, 2022).
  - Support to draft a cybersecurity guideline for supervised financial institutions and a supervisory manual.
  - High-level assessments of CBTT cybersecurity governance and the Identity and Access Management (IAM) project.
- Coordination:
  - CBTT established a working group comprising CBTT, Trinidad and Tobago Securities and Exchange Commission (TTSEC), Financial Intelligence Unit of Trinidad and Tobago (FIUTT), and Office of the Commission of Cooperative Development (CCD). CBTT will lead drafting of the guideline and intends to issue it to entities regulated by CBTT.
  - For the CBTT cybersecurity project, an internal project team has been constituted.

### Seminar on Cybersecurity Regulation (November 1–3, 2022)
- Objectives:
  - Build capacity among supervisory staff to draft a regulatory guideline.
  - Topics covered: cyber threat landscape; cyber risk and financial stability; impact of new technologies on cyber risk; international regulatory practices; cyber risk governance and management best practices; third party risk management; incident reporting; business continuity planning, response and recovery; information sharing; testing.
- Attendance: Supervisory officials from all regulatory authorities attended in person and remotely. At the time of the mission, CBTT was the only regulator intending to draft a guideline.
- Structure: Three days with three sessions each day; agenda provided in Annex I.
- Session highlights:
  - Day 1: Cyber Risk and Financial Sector – An Introduction; Implications for Financial Stability; Cyber Security – An Overarching Framework; Cyber Security and New Technologies including Cloud Regulation. Discussed AI/Machine Learning, Application Programming Interface, and Cloud Technologies.
  - Day 2: International Guidance on Cyber Risk and Global Regulatory Practices; third-party risk management; governance and risk management aspects.
  - Day 3: Incident reporting; information sharing; business continuity and response and recovery capabilities. Covered ongoing work by standard setting bodies on incident reporting and voluntary information sharing among financial institutions.

### Regulatory context and need for a dedicated guideline
- Current regulatory landscape:
  - No Information and Communication Technology (ICT) or Cyber risk guidelines issued by the CBTT.
  - ICT/cyber aspects are governed indirectly by extant instructions on corporate governance, market conduct, security systems for safeguarding customer information, Internal Capital Adequacy Assessment Process (ICAAP), and outsourcing.
- Observed gap:
  - Regulated entities may not consider existing instructions to be directly applicable to ICT/cyber risk management, underlining the need for a separate regulatory guidance.
- CBTT intention:
  - Develop a draft guideline for consultation with its regulated institutions in the first quarter of 2023.

### Supervisory capacity assessment (FISD) — findings and gaps
- Organizational and resourcing observations:
  - Supervisory responsibilities for banks and nonbanks are entrusted to one division; insurance and pension firms to another.
  - No practice of assigning a dedicated supervisor even for the top five banks; similar arrangements apply to insurance and pension firms.
  - Resource constraints need to be addressed urgently to increase frequency and intensity of ICT/cyber examinations, particularly for large banks.
- Current supervisory activities and gaps:
  - CBTT has conducted thematic reviews of banks periodically on cyber related topics, carried out cyber risk assessments for banks, and sensitized financial sector participants.
  - Insurance and pension firms have not been subjected to any survey on cyber related topics; regulatory/supervisory initiatives for these firms are limited.
- Staffing and asset shares:
  - Number of supervisory staff allocated to supervision of banks / nonbanks: 16 (includes the manager and administrative assistant).
  - Among bank / nonbank supervisors only one Junior Examiner is an IT qualified resource partially marked for such work; among insurance supervisors, no such resource is available.
  - Asset shares by entity type: banks/insurance/pension firms have a share in total assets of 60/20/20 percent respectively.
- Short-term mitigation: Leverage ICT/cyber expertise in CBTT’s Risk Management and Audit functions for supervisory purposes, noting coordination and ownership risks.
- Supervisory practice limitations:
  - Thematic reviews and surveys are infrequent; four surveys conducted in the past eight years.
  - Onsite supervision focusing on ICT/cyber risk and offsite capabilities are very limited.
  - RBS Manual is dated (version shared with the mission is dated 2003) and due for revision in 2023.

### Cybersecurity governance at CBTT — assessment and recommendations
- Key governance findings:
  - Cybersecurity governance broadly set up according to generally accepted practices, with some minor differences and resource constraints.
  - Information security function in the first line is subordinated to the Head of IT, creating conflict-of-interest risks that require compensating controls.
  - The second line (risk management) has a formal responsibility in driving IT governance, a role typically operational and in the first line.
  - Cybersecurity policies and procedures cover most important topics and have been recently updated, but lack secure application development standards and security hardening baselines.
  - Payment systems cybersecurity policies are uneven; SWIFT CSP environment is more comprehensive.
  - Regular recovery tests of critical systems are not performed beyond tabletop exercises; recovery site configured to provide selected critical services only.
- Internal governance recommendations (selected):
  - Assess workload of the IT Security unit and increase resources as needed (Priority: High; Time frame: Medium term; Reference Paragraph: 32).
  - Remove IT governance from the responsibilities of the risk function (Priority: High; Time frame: Near term; Reference Paragraph: 33).
  - Establish regular cybersecurity meetings and reporting at the Board level with the participation of the Head of IT Security (Priority: High; Time frame: Near term; Reference Paragraph: 34).
  - Develop a secure application development policy and security hardening baselines (Priority: High; Time frame: Near term; Reference Paragraph: 35).
  - Develop a policy to bring the cybersecurity controls of the ACH and RTGS systems more in line with the SWIFT CSP (Priority: High; Time frame: Near term; Reference Paragraph: 36).
  - Regularly commission security reviews and tests of the payment systems (Priority: High; Time frame: Near term; Reference Paragraph: 37).
  - Disaster recovery tests should include simulating a complete failure in the primary data center (Priority: High; Time frame: Medium term; Reference Paragraph: 38).

### Identity and Access Management (IAM) project — status, findings, and recommendations
- Project status and governance:
  - The IAM project has been formally set up and is in Phase 1, which is preparatory.
  - Project charter and project plan exist; core project team consists of staff from the IT and IT security departments.
  - Phase 1 deliverables are identified; Phase 1 ends on January 31, 2022.
- Key findings:
  - The project is in a very early stage; follow-up mission in the first quarter of 2023 would be better positioned to assess (Finding 40).
  - The project charter does not specify time commitments in FTEs; mission cautioned high workload and need for business function involvement (Finding 41).
  - It is unlikely that the budget of TTD 100,000 (approximately USD 14,700) set aside for IAM advisory services will be sufficient (Finding 43).
- Recommendations (items 44–47):
  - Plan out Phase 2 of the IAM project and include requirements definition and roles and access rights review and reengineering as key tasks (Recommendation 44).
    - Suggested schedule: Begin planning in November 2022 with Phase 2 commencing in February 2023 and ideally finishing in a few months’ time.
    - Requirements scope: functional, non-functional, and security requirements; roles and access rights review to identify inconsistencies and apply least privilege.
  - Analyze projected workload and expertise required vs internal resources and skills to determine type and extent of third-party support to be sourced (Recommendation 45).
    - Deliverable: Estimate total effort in FTEs (or man-days or work hours); identify expertise gaps.
  - Adopt a phased approach to IAM deployment (Recommendation 46).
    - Pilot suggestion: First deployment could include Active Directory and one or two internally developed applications.
  - Adopt good IAM implementation practices listed in the report as deemed necessary (Recommendation 47).

### Secure application development policy and security hardening baselines (item 35)
- Secure application development policy — objectives and requirements:
  - CBTT conducts internal (in-house) application development, including security sensitive functionalities.
  - Policy objectives:
    - Mandate development methods and coding approaches that promote security by design.
    - Require code reviews.
    - Require testing for exploitable bugs.
    - Require secure configuration of the development toolchain.
- Separation of environments and access controls:
  - Strict separation of development, test and production environments is needed.
  - Restrict developer access to production systems to reduce accidental or malicious changes and exposure of sensitive data.
- Security hardening baselines:
  - Establish and enforce baseline configurations for servers, workstations, networking devices, etc., to decrease the attack surface.

### Payment systems cybersecurity (items 36–38) — specific measures and frequencies
- Recommendation (36): Develop a policy to bring ACH and RTGS cybersecurity controls more in line with the SWIFT CSP.
- Recommendation (37): Regularly commission security reviews and tests of the payment systems.
  - Current practice: CBTT uses a scanning tool to mitigate unpatched vulnerabilities.
  - Recommended augmentations:
    - Security configuration reviews, access rights reviews, network security reviews.
    - Security testing, such as penetration tests.
  - Frequency guidance:
    - Penetration tests and security reviews: typically annual.
    - Vulnerability scans: more frequent (e.g., weekly, monthly, or quarterly); minimum requirement for scanning frequency: quarterly and after any significant changes.
- Recommendation (38): Disaster recovery tests should progress beyond tabletop exercises and include simulating a complete failure in the primary data center.
  - Suggested approach: Perform a full recovery using offsite resources as far as possible; consider more disruptive tests after gaining experience.

### Table 1 — Key supervisory and regulatory recommendations (selected highlights)
- Organization and capacity
  - Augment the resources in ICT/cyber risk supervision — Priority: High; Time frame: Immediate; Reference Paragraph: 15
- Cyber Risk Regulation
  - Draft the guideline on ICT/cyber risk covering banks, insurance companies and pension firms — Priority: High; Time frame: Near Term; Reference Paragraph: 16
  - Include provision for independent periodic assessment by qualified external professionals — Priority: Medium; Time frame: Near Term; Reference Paragraph: 17
  - Require Boards to identify regulatory gaps, draw implementation plans with milestones, and submit to CBTT — Priority: High; Time frame: Near Term; Reference Paragraph: 18
  - Prepare a cyber incident reporting template and require supervised entities to report cyber incidents — Priority: High; Time frame: Near Term; Reference Paragraph: 20
  - Sensitize regulated entities on need for strengthening cybersecurity and information sharing among banks — Priority: High; Time frame: Near Term; Reference Paragraph: 21
- Cyber Risk Supervision
  - Plan and conduct ICT/cyber preparedness surveys among insurance companies and pension firms — Priority: High; Time frame: Medium Term; Reference Paragraph: 22
  - Increase frequency and intensity of ICT/cyber risk assessments, starting with major banks — Priority: High; Time frame: Medium Term; Reference Paragraph: 23
  - Plan and augment supervisory resources to ensure a self-sufficient supervision function covering banks, insurance companies and pension firms — Priority: High; Time frame: Medium Term; Reference Paragraph: 24
  - Consider setting up an offsite supervision function for ICT/cyber risks — Priority: Medium; Time frame: Medium Term; Reference Paragraph: 25
- Identity and Access Management (IAM) project
  - Plan Phase 2 including requirements definition and roles/access rights review — Priority: High; Time frame: Near term; Reference Paragraph: 44
  - Analyze projected workload and expertise vs internal resources to determine third-party support needed — Priority: High; Time frame: Near term; Reference Paragraph: 45
  - Adopt a phased approach to IAM deployment — Priority: High; Time frame: Near term; Reference Paragraph: 46
  - Adopt good IAM implementation practices listed in the Appendix as deemed necessary — Priority: Medium; Time frame: Near term; Reference Paragraph: 47

*Immediate: less than three months; Near term (NT): 3–6 months; Medium term (MT):6–12 months; Long term (LT): more than 12 months.*

*Source: 1ttoea2023002 - Preface*

### Preface.................................................................................................................

### Preface

### Mission purpose and scope
- At the request of the Central Bank of Trinidad and Tobago (CBTT), the Monetary and Capital Markets Department (MCM) provided a field based technical assistance (TA) mission on strengthening cybersecurity in financial institutions during October 31 to November 4, 2022.
- The mission objectives were:
  - (i) to strengthen the cybersecurity of the financial institutions under the supervisory ambit of CBTT; and
  - (ii) to strengthen the cybersecurity posture of the Central Bank.
- The mission met the Governor on the first day and met Patrick Solomon (Inspector), Michelle Francis-Pantor (Deputy Inspector) from Financial Institutions Supervision Department (FISD) and Frances Correa (IT Consultant) and their team members.
- This report presents the mission’s assessment and main conclusions.

*Source: 1ttoea2023002 - Preface*

### Deliverables and initial arrangements
- Deliverables included:
  - A capacity building seminar on regulation of cyber risk (delivered November 1–3, 2022).
  - Support to draft a cybersecurity guideline for supervised financial institutions and a supervisory manual.
  - High-level assessments of CBTT cybersecurity governance and the Identity and Access Management (IAM) project.
- For strengthening cybersecurity of financial institutions, CBTT established a working group comprising all the financial regulators: CBTT, Trinidad and Tobago Securities and Exchange Commission (TTSEC), the Financial Intelligence Unit of Trinidad and Tobago (FIUTT), and the Office of the Commission of Cooperative Development (CCD). CBTT will lead drafting of the guideline and intends to issue it to entities regulated by CBTT.
- For the CBTT cybersecurity project, an internal project team has been constituted.

### Seminar on Cybersecurity Regulation (November 1–3, 2022)
- Seminar objectives and scope:
  - Build capacity among supervisory staff to draft a regulatory guideline.
  - Cover topics: cyber threat landscape, cyber risk and financial stability, impact of new technologies on cyber risk, international regulatory practices, cyber risk governance and management best practices, third party risk management, incident reporting, business continuity planning, response and recovery, information sharing, and testing.
- Attendance:
  - Supervisory officials from all regulatory authorities attended in person and remotely. At the time of the mission, CBTT was the only regulator intending to draft a guideline.
- Seminar structure:
  - Three days with three sessions each day; agenda provided in Annex I.
- Session highlights:
  - Day 1: Cyber Risk and Financial Sector – An Introduction; Implications for Financial Stability; Cyber Security – An Overarching Framework; Cyber Security and New Technologies including Cloud Regulation. Discussed AI/Machine Learning, Application Programming Interface, and Cloud Technologies.
  - Day 2: International Guidance on Cyber Risk and Global Regulatory Practices; third-party risk management; governance and risk management aspects.
  - Day 3: Incident reporting; information sharing; business continuity and response and recovery capabilities. Covered ongoing work by standard setting bodies on incident reporting and voluntary information sharing among financial institutions.

### Regulatory context and need for a dedicated guideline
- Current regulatory landscape:
  - No Information and Communication Technology (ICT) or Cyber risk guidelines issued by the CBTT.
  - ICT/cyber aspects are governed indirectly by extant instructions on corporate governance, market conduct, security systems for safeguarding customer information, Internal Capital Adequacy Assessment Process (ICAAP), and outsourcing.
- Observed gap:
  - Discussions with a couple of banks indicate regulated entities may not consider the existing instructions to be directly applicable to ICT/cyber risk management, underlining the need for a separate regulatory guidance.
- CBTT intention:
  - Develop a draft guideline for consultation with its regulated institutions in the first quarter of 2023.

### Supervisory capacity assessment (Financial Institutions Supervision Department - FISD)
- Organizational and resourcing observations:
  - Supervisory responsibilities for banks and nonbanks are entrusted to one division; insurance and pension firms to another.
  - There is no practice of assigning a dedicated supervisor even for the top five banks; similar arrangements apply to insurance and pension firms.
  - Resource constraints within FISD need to be addressed urgently to increase frequency and intensity of ICT/cyber examinations, particularly for large banks.
- Current supervisory activities and gaps:
  - CBTT has conducted thematic reviews of banks periodically on cyber related topics, carried out cyber risk assessments for banks, and sensitized financial sector participants on the need for enhanced cybersecurity.
  - Insurance and pension firms have not been subjected to any survey on cyber related topics; regulatory/supervisory initiatives to address ICT/cyber risks for these firms are limited.
- Recommended supervisory actions (see Table 1 summary below for priorities and timeframes).

### Cybersecurity governance assessment (CBTT)
- Assessment approach:
  - High-level review of organizational and project structures, policies and procedures, and interviews with selected members of CBTT management and staff.
- Key findings:
  - (i) Cybersecurity governance at CBTT is set up according to generally accepted practices in the financial sector, with some minor differences and resource constraints.
  - (ii) The information security function in the first line is subordinated to the Head of IT, which calls for compensating controls.
  - (iii) Unusually, the second line of defense–risk management–has a formal responsibility in driving IT governance, a first-line role.
  - (iv) Cybersecurity policies and procedures cover most of the important topics and have been recently updated.
  - (v) Policies governing the cybersecurity of payment systems are uneven in terms of the technical controls required. The SWIFT cybersecurity control environment is more comprehensive due to the formalized requirements of the Customer Security Program (CSP).
  - (vi) There is not a separate Cyber Risk Committee or similar at the Board level, but the existing IT Committee assumes this function.

### Identity and Access Management (IAM) project assessment
- Project status and governance:
  - The IAM project has been formally set up and is now in Phase 1, which is considered preparatory.
  - The governance of the project, the high-level roadmap, and the deliverables for Phase 1 are generally in line with good practices.
- Near-term attention items identified by the mission:
  - Get input from the business functions.
  - Conduct a roles and access rights review.
  - Develop formal requirements.
- Appendix I provides a summary of recommended actions and selected good IAM project practices.

### Table 1 – Key recommendations (selected highlights with Priority and Time frame)
- Organization and capacity
  - Augment the resources in ICT/cyber risk supervision — Priority: High; Time frame: Immediate; Reference Paragraph: 15
- Cyber Risk Regulation
  - Draft the guideline on ICT/cyber risk covering banks, insurance companies and pension firms on the basis of various inputs provided in the Seminar on Regulations, striking an appropriate balance between general principles and specific details having regard to the local environment and digital landscape — Priority: High; Time frame: Near Term; Reference Paragraph: 16
  - Include a provision in the guideline to conduct an independent periodic assessment of cyber preparedness of banks, insurance companies and pension firms by qualified external professionals — Priority: Medium; Time frame: Near Term; Reference Paragraph: 17
  - Incorporate a requirement for the Board to identify the regulatory gaps, draw an implementation plan with appropriate milestones and submit to the CBTT as part of the guideline — Priority: High; Time frame: Near Term; Reference Paragraph: 18
  - Prepare a cyber incident reporting template and require supervised entities to report cyber incidents in keeping with the requirements as defined in the guideline or template — Priority: High; Time frame: Near Term; Reference Paragraph: 20
  - Sensitize the regulated entities on the need for strengthening cybersecurity through speeches, interviews, etc., and impress upon the need for a separate guideline, cyber incident reporting and information sharing among banks — Priority: High; Time frame: Near Term; Reference Paragraph: 21
- Cyber Risk Supervision
  - Plan and conduct ICT/cyber preparedness surveys among insurance companies and pension firms — Priority: High; Time frame: Medium Term; Reference Paragraph: 22
  - Increase the frequency and intensity of ICT/cyber risk assessments, to start with for major banks — Priority: High; Time frame: Medium Term; Reference Paragraph: 23
  - Plan and augment supervisory resources to ensure a self-sufficient supervision function covering banks, insurance companies and pension firms — Priority: High; Time frame: Medium Term; Reference Paragraph: 24
  - Consider setting up an offsite supervision function for ICT/cyber risks — Priority: Medium; Time frame: Medium Term; Reference Paragraph: 25
- Cybersecurity governance (CBTT)
  - Assess the workload of the IT Security unit and increase resources as needed — Priority: High; Time frame: Medium term; Reference Paragraph: 32
  - Remove IT governance from the responsibilities of the risk function — Priority: High; Time frame: Near term; Reference Paragraph: 33
  - Establish regular cybersecurity meetings and reporting regime at the Board level with the participation of the Head of IT Security — Priority: High; Time frame: Near term; Reference Paragraph: 34
  - Develop a secure application development policy and security hardening baselines — Priority: High; Time frame: Near term; Reference Paragraph: 35
  - Develop a policy to bring the cybersecurity controls of the ACH and RTGS systems more in line with the SWIF CSP — Priority: High; Time frame: Near term; Reference Paragraph: 36
  - Regularly commission security reviews and tests of the payment systems — Priority: High; Time frame: Near term; Reference Paragraph: 37
  - Disaster recovery tests should include simulating a complete failure in the primary data center — Priority: High; Time frame: Medium term; Reference Paragraph: 38
- Identity and Access Management (IAM) project
  - Plan out Phase 2 of the IAM project and include requirements definition and roles and access rights review as key tasks, among others — Priority: High; Time frame: Near term; Reference Paragraph: 44
  - Analyze the projected workload and expertise vs internal resources and skills to determine the type and extent of third-party support needed — Priority: High; Time frame: Near term; Reference Paragraph: 45
  - Adopt a phased approach to IAM deployment — Priority: High; Time frame: Near term; Reference Paragraph: 46
  - Adopt good IAM implementation practices listed in the Appendix as deemed necessary — Priority: Medium; Time frame: Near term; Reference Paragraph: 47

*Immediate: less than three months; Near term (NT): 3–6 months; Medium term (MT):6–12 months; Long term (LT): more than 12 months.*

*Source: 1ttoea2023002 - Preface*

### 7. CBTT does not currently have a cybersecurity guideline in place applicable to its

### 7. CBTT does not currently have a cybersecurity guideline in place applicable to its supervised entities

### Current regulatory coverage and gaps
- Existing guidelines that touch on ICT/cyber risk management: Corporate Governance Guideline; Guideline for the Management of Outsourcing Risks; Guideline for the Security Systems for Safeguarding Customer Information; Market Conduct Guideline; ICAAP Guideline.
- Aspects covered by these fragmented guidelines:
  - (i) Board having special skills including information technology.
  - (ii) Risk management framework to include provisions to evaluate the risks and materiality of all existing and prospective outsourcing arrangements and the inherent risks associated with outsourcing which includes cyber risk.
  - (iii) Management to be responsible for developing and documenting an operating manual of the policies, procedures and processes of the institution’s information security program.
  - (iv) Reporting of material incidents to the CBTT.
  - (v) Need to conduct stress tests with severe cyberattack as one of the scenarios.
- Conclusion: The current regulatory guidelines on the subject are fragmented and do not comprehensively address the issues given the growing importance of cybersecurity.

### Institutional roles and draft-guideline initiative
- CBTT has identified the regulatory gap and constituted a working group represented by all financial sector regulators to draft a guideline.
- Supervisory responsibilities:
  - CBTT: supervising banks, non-banks, insurance companies, pension firms, bureaux de change, and payment systems.
  - Trinidad and Tobago Security and Exchange Commission (TTSEC): supervises the securities market and intermediaries.
  - Cooperative Development Division (Ministry of Youth and National Development): supervises credit unions.
  - Financial Intelligence Unit: jurisdiction over Anti Money Laundering/Countering Financing of Terrorism across various nonfinancial sectors.
- Only CBTT proposes to draft the guideline; other regulators expect lessons learned will be used to introduce similar guidelines later.
- Working group discussions provided inputs on scope, applicability, proportionality, need to elaborate instructions based on local needs, technology neutrality, and outcome focus. The drafting burden is primarily on CBTT.

### Readiness across supervised entities
- Banks are better informed on ICT/cyber risks than insurance and pension firms.
  - FISD focus on banks’ IT systems; certain guidelines make it incumbent on banks to manage IT risks.
  - Periodic surveys by CBTT have contributed to bank sensitization.
  - RBS Manual covers assessment of IT risks as part of operational risk but is outdated (version shared with the mission is dated 2003) and due for revision in 2023.
  - Desk-based reviews through virtual engagement with banks are positive initiatives.
  - FISD used FFIEC cybersecurity assessment tool to assess banking sector exposures.
- Insurance firms have not received similar engagements, leaving a preparedness gap.
- Stakeholder discussions with two major banks revealed:
  - Banks are considering ICT/cyber risks and have taken mitigation steps.
  - One locally headquartered bank has several subsidiaries in multiple countries increasing IT service management burdens.
  - A foreign-owned local subsidiary outsources most IT services to its parent abroad, limiting local capacity.
  - Both banks could not readily recall the fragmented range of applicable regulatory guidelines.
  - Willingness to report cyber incidents to CBTT exists, but reservations persist about sharing information among peers.

### Supervisory capacity and practices
- Resource constraints in ICT/cyber risk supervision are acute:
  - Only one junior examiner earmarked partially for banks and none for insurance and pension firms.
  - Organizational structure: supervision of banks/nonbanks entrusted to one division and insurance/pension firms to another.
  - Within banks & nonbanks division, supervised entities allocated among three teams collectively responsible; dedicated supervisors for top five banks not typical.
  - Number of supervisory staff allocated to supervision of banks / nonbanks at 16 (includes the manager and administrative assistant).
  - Among bank / nonbank supervisors only one Junior Examiner is an IT qualified resource partially marked for such work; among insurance supervisors, no such resource is available.
  - Asset shares by entity type: banks/insurance / pension firms have a share in total assets of 60/20/20 percent respectively.
- Short-term mitigation: leverage ICT/cyber expertise in CBTT’s Risk Management and Audit functions for supervisory purposes, though this can create coordination issues and potential lack of ownership.
- Supervisory practices:
  - Thematic reviews and surveys are infrequent; four surveys conducted in the past eight years.
  - For banks, FISD leverages external and internal audit work; no prescribed testing requirements.
  - Onsite supervision focusing on ICT/cyber risk and offsite capabilities are very limited.
  - RBS manual is dated and requires urgent update; priority to update will follow completion of the cybersecurity guideline.

### Cybersecurity governance at CBTT — assessment
- Overall setup aligns with generally accepted good practices; all three lines of defense (management control, risk management, internal audit) have cybersecurity capabilities.
- Resource constraints are more apparent in the first line; second and third lines less strained.
- Unusual assignment: the second line (risk management) has formal responsibility for driving IT governance, a role typically not operational for second-line functions.
- Information security function in the first line is subordinated to the Head of IT — an arrangement with conflict-of-interest risks but some operational advantages when compensated by controls.
- Cybersecurity policies and procedures recently updated but missing secure application development standards and security hardening baselines.
- Payment systems cybersecurity policies vary in technical control requirements; SWIFT CSP environment is more comprehensive.
- Regular recovery tests of critical systems are not performed beyond tabletop exercises; recovery site is configured to provide selected critical services only.

### Recommendations (supervisory coverage and resourcing)
- Augment the resources in ICT/cyber risk supervision.
  - Rationale: rapid digitalization, adoption of newer technologies, increasing consumer demand for digital services will raise supervisory workload (drafting guideline, industry consultation, finalization, issuance, and subsequent compliance assessment).
  - Current staffing (one Junior Examiner partially for banks/nonbanks; none for insurance/pension firms) suggests urgent need to augment supervisory resources.
- Draft the guideline on ICT/cyber risk covering banks, insurance companies and pension firms based on Seminar on Regulations inputs.
  - Include all three sectors; allow flexibility in implementation for insurance and pension firms as needed.
- Include provision for independent periodic assessment of cyber preparedness by qualified external professionals.
  - Leverage external audit firms given acute supervisory resource shortage; many jurisdictions require periodic assessments and submission of such reports for central bank perusal.
- Require Boards to identify regulatory gaps, draw implementation plans with milestones, and submit to CBTT.
  - Consider standard requirement in guidelines for institutions to conduct gap analyses and submit at regular intervals to inform supervisory assessment of progress.
- Determine level of detail in the guideline considering local environment and digital landscape.
  - While principle-based guidance is welcome, provide sufficient detail to facilitate implementation based on Boards’ expertise and local factors.
- Prepare a cyber incident reporting template and require regular reporting by supervised entities.
  - Regular cyber incident reporting benefits both supervisor and supervised entities; integrate into the guideline.
- Sensitize regulated entities on strengthening cybersecurity through speeches, interviews, and emphasize cyber incident reporting and information sharing among banks.
  - The drafting and approval process can take up to six months; early sensitization recommended.
- Plan and conduct ICT/cyber preparedness surveys among insurance companies and pension firms to close current exposure gaps.
- Increase frequency and intensity of ICT/cyber risk assessments, starting with major banks given their asset share and faster technology adoption.
- Plan and augment supervisory resources to ensure a self-sufficient supervision function covering banks, insurance companies, and pension firms.
  - Supervisors must maintain a macro perspective on interdependencies, interconnections, concentration risk, and financial stability implications.
  - Bringing insurance and pension firms into scope will require substantial education and awareness work.
- Consider setting up an offsite supervision function for ICT/cyber risks.
  - Offsite capabilities should collect KPIs, cyber incidents (individual major incidents and summary level), organizational structures, digital products, third-party arrangements, test reports, and policy documents to prepare a risk profile/dashboard per supervised entity and a macro picture of the sector.

### Recommendations (CBTT internal cybersecurity governance)
- Assess workload of the IT Security unit and increase resources as needed.
  - Perform analysis of current workload, including operations and project work.
  - Rule of thumb cited: information security workforce Full Time Equivalent (FTE) is typically in the 10-15 percent range of the IT workforce FTE in banking; given CBTT operates critical infrastructure, the actual ratio may be closer to the upper bound.
- Remove IT governance from the responsibilities of the risk function.
  - Risk function should focus on risk data collection, consolidation, analysis, and reporting, not operational governance matters including IT and cybersecurity.
  - IT and cybersecurity governance should be assigned to IT department and IT Security unit respectively, under senior management direction and internal audit review.
- Establish regular cybersecurity meetings and reporting at the Board level with participation of the Head of IT Security.
  - A "dotted line" reporting arrangement or elevating IT Security to the same level as IT would mitigate conflict-of-interest risks where IT Security is subordinated to IT management.

*IMF | TRINIDAD AND TOBAGO                      Strengthening Cybersecurity in Financial Institutions*

### 35. Develop a secure application development policy and security hardening baselines.

### 35. Develop a secure application development policy and security hardening baselines.

### Secure application development policy
- Finding: CBTT does internal (in-house) application development, including security sensitive functionalities.
- Rationale: Security vulnerabilities in software often occur because of insufficient focus on secure development practices.
- Policy objectives:
  - Mandate development methods and coding approaches that promote security by design.
  - Require code reviews.
  - Require testing for exploitable bugs.
  - Require secure configuration of the development toolchain.

### Separation of environments and access controls
- Finding: A related area needing attention is the strict separation of the development, test and production environments and restricting access of developers to production systems.
- Rationale: Limiting developer access to production reduces the risk of accidental or malicious changes and exposure of sensitive data.

### Security hardening baselines
- Finding: Security hardening baselines help improve security by mandating configuration settings on servers, workstations, networking devices, etc., that decrease the attack surface.
- Recommendation: Establish and enforce baseline configurations for all relevant assets (servers, workstations, networking devices).

### Payment systems cybersecurity (items 36–38)
- Recommendation (36): Develop a policy to bring the cybersecurity controls of the ACH and RTGS systems more in line with the SWIFT CSP.
  - Rationale: The SWIFT CSP encapsulates best practice in payment system related cybersecurity control and thus can form a strong basis for improving the cybersecurity of other payment systems.
- Recommendation (37): Regularly commission security reviews and tests of the payment systems.
  - Current practice: CBTT uses a scanning tool to mitigate the risk posed by unpatched vulnerabilities.
  - Recommended augmentations:
    - Security configuration reviews, including access rights reviews and network security reviews.
    - Security testing, such as penetration tests.
  - Frequency guidance:
    - Typically, penetration tests and security reviews of payment systems are done annually.
    - More frequent (e.g., weekly, monthly, or quarterly) vulnerability scans in between.
    - Minimum requirement for scanning frequency: quarterly and after any significant changes.
- Recommendation (38): Disaster recovery tests should progress beyond tabletop exercises and include simulating a complete failure in the primary data center.
  - Suggested approach:
    - Perform a full recovery using the offsite resources as far as possible.
    - Consider more disruptive tests (e.g., shutting down the data center) after gaining experience.
    - Note: Such disruptive tests require extensive preparation and planning and will typically be performed less frequently.

---

### V. IDENTITY AND ACCESS MANAGEMENT PROJECT

### Assessment (items 39–43)
- Finding (39): The IAM project is set up according to good project management practices; there is a project charter and a project plan.
- Finding (40): The project is in a very early stage; the mission could not meaningfully assess performance and delivery against plans. A follow-up mission in the first quarter of 2023 would be better positioned to assess.
- Finding (41): Core project team consists of staff from the IT and IT security departments. The project charter does not specify time commitments needed from staff (e.g., in FTEs). The mission cautioned high workload and the need for business function involvement.
- Finding (42): Deliverables for Phase 1 are clearly identified and creating them within the deadline seems feasible. Phase 1 ends on January 31, 2022. Activities include contacting potential vendors for general information, scheduled review of the IAM policy, and work on the authoritative source for identity information.
- Finding (43): It is unlikely that the budget of TTD 100,000 (approximately USD 14,700) set aside for IAM advisory services will be sufficient.
  - Rationale: External advisors typically provide IAM-specific subject matter knowledge, methodology and tools, assist in requirements definition, role review and reengineering, solution design, vendor selection, and quality assurance and post-implementation review. Given the size and complexity, the budget could be exhausted by just one of these tasks.

### Recommendations (items 44–47)
- Recommendation (44): Plan out Phase 2 of the IAM project and include requirements definition and roles and access rights review and reengineering as key tasks.
  - Suggested schedule: Begin planning in November 2022 with Phase 2 commencing in February 2023 and ideally finishing in a few months’ time.
  - Requirements scope:
    - Functional requirements: workflow and policy management, interfacing and integration, search and analytics.
    - Non-functional requirements: performance, availability, usability, and security.
    - Security requirements: logical access and data security controls, and logging and monitoring.
  - Roles and access rights review:
    - Identify inconsistent, conflicting, or missing role definitions.
    - Identify access rights non-compliance with policy.
    - Input to role reengineering to reduce the number of roles and fine-tune access rights to adhere to least privilege and need-to-know principles.
    - Business functions must be involved in role review and reengineering.
- Recommendation (45): Analyze projected workload and expertise required vs internal resources and skills to determine type and extent of third-party support to be sourced.
  - Deliverable: Estimate total effort in FTEs (or man-days or work hours).
  - Identify expertise gaps (typical shortages: role reengineering, access rights review, interface development, system integration).
- Recommendation (46): Adopt a phased approach to IAM deployment.
  - Deployment approach: Deploy selected IAM solution over several phases to reduce risk of widespread disruption.
  - Pilot suggestion: First deployment phase could include Active Directory and one or two internally developed applications to gain operational experience in a limited live environment.
- Recommendation (47): Adopt good IAM implementation practices listed in the report as deemed necessary.
  - Note: Good practices in the Appendix can guide decisions on project structure and execution.

---

### Annex I — Selected good IAM project practices (summary of key points)
- Requirements and vendor selection
  - Develop both functional and non-functional requirements with stakeholder representation (IT, information security, business units).
  - Prioritize requirements (e.g., must-have, negotiable, nice-to-have) including workflow, interfacing, integration, batch processing, analytics, search, and security.
  - Define and prioritize requirements for IAM-related services (role reengineering, quality assurance, security testing, post-implementation review).
  - Conduct initial market research to identify not more than three to four potential IAM products/vendors.
  - Reduce candidates to typically three, informally check capabilities, references, and reputation.
  - Issue a formal Request for Information (RFI); run product test drives and demonstrations.
  - Issue a formal Request for Proposal (RFP) including total cost of ownership for several years, using a template for comparative analysis.
  - Assess financial and technical proposal information separately using predefined and weighted criteria.
  - Use a simplified, similar process for selecting independent advisors where appropriate.
- Implementation practices
  - Raise awareness and secure buy-in from key stakeholders; sponsors should promote the effort.
  - Treat IAM as both a business and IT endeavor; involve business units in planning, role review, reengineering, and testing.
  - Identify types of user identities (human, non-human/service accounts, employee, contractor, supplier, etc.) and consolidate to the minimum necessary.
  - Identify all systems users have access to, irrespective of initial IAM scope.
  - Perform identity and access reviews at least for systems in pilot and first deployment phases.
  - Identify authoritative source for identity information early and explore interfacing/synchronization.
  - Involve external advisors for quality assurance early if used.
  - Define a pilot phase with limited scope that includes a “difficult” system (e.g., in-house development without standard connector).
  - Deploy in phases according to a roll-out plan; have a roll-back plan; test roll-out and rollback before live deployment.
  - Use a segregation of duties matrix for IAM access rights setup.
  - Security-harden and test IAM infrastructure before deployment.
  - Develop a knowledge base focused on provisioning and lifecycle management issues.
  - Conduct a post-implementation review after the first or second deployment phase.

*Source: 1ttoea2023002 - 35. Develop a secure application development policy and security hardening baselines.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2023/english/1ttoea2023002.pdf_
